Posts

IAM and PAM: Why Identity Is the Real Cybersecurity Perimeter in 2026

Image
For years, cybersecurity was built around a simple idea: keep the bad guys out of the network. Firewalls, VPNs, perimeter controls - that was the playbook. In 2026, that model is dead. Your data lives in the cloud. Your users work everywhere. Your attackers don't break in - they log in. And that's why Identity and Access Management (IAM) and Privileged Access Management (PAM) are no longer "security tools" they are control systems for modern businesses and the foundation of modern cyber resilience . The Hard Truth: Most Breaches Are Identity Failures The numbers are no longer debatable: Credential theft surged 160% in 2025 , with 1.8 billion credentials compromised in just six months. dailysecurityreview 78% of breaches now involve unauthorized access - attackers logging in, not breaking in. dailysecurityreview Look at almost any major breach in the last few years - government, enterprise, or SMB - and the pattern is consistent: S...

ASIC Action Against FIIG Securities Is a Line in the Sand for Cybersecurity in Australia

Image
$2.5 million. That’s what ASIC has now forced FIIG Securities Limited (FIIG) to pay not simply for suffering a breach, but for failing to maintain adequate cybersecurity controls for more than four years . This isn’t just another breach headline. It’s a regulatory turning point for every Australian Financial Services (AFS) licensee and a warning shot for boards and exec teams still treating cyber as an “IT problem”. In 2026, ASIC has made the message clear: Cyber resilience is now a licence-to-operate issue. What Actually Happened at FIIG According to ASIC, FIIG’s cyber security failures occurred between 13 March 2019 and 8 June 2023 . Those failures worsened the impact of a 2023 cyber attack that saw around 385GB of confidential data stolen and sensitive client information leaked on the dark web. The compromised data included: Driver’s licences Passport information Bank account details Tax File Numbers (TFN...

Why North Korean Hackers Are Targeting Devs Through Visual Studio Code Projects

Image
There’s a new backdoor campaign going around. It’s slick, it’s persistent, and it’s targeting developers — specifically those using Microsoft Visual Studio Code (VS Code) as part of their day-to-day workflow. This one’s coming out of North Korea. And it's not just some throwaway malware — it's part of a broader shift in how state-linked actors are slipping past traditional defences by piggybacking off developer tools and trusted platforms. The Basics: Dev Tools as Attack Vectors Security researchers at Jamf Threat Labs have uncovered the latest iteration of an ongoing campaign (nicknamed Contagious Interview ) that’s weaponising VS Code projects. The method? Attackers instruct targets — usually software engineers — to clone a GitHub, GitLab, or Bitbucket repository and open it in VS Code. They pose as recruiters or hiring managers offering a technical assessment. Once the repo is opened, a malicious tasks.json file is silently executed in the background — taking adv...

🧠 “The 2026 Cyber Stack: What Stays, What Goes, What’s Overhyped”

Image
  We don’t need more tools. We need fewer excuses. In 2026, the average Australian org is still juggling 40+ cyber vendors. That’s not security — that’s bloat. I’ve worked with CISOs, IT leads and boardrooms across government, enterprise, MSPs and SMBs. The story is the same: “We’ve spent the money. Why aren’t we safer?” Because buying tech isn’t a strategy. And most cyber stacks are built on legacy thinking — not business outcomes. Here’s my breakdown of what stays, what goes, and what’s overhyped in the 2026 cyber landscape. ✅ What Stays: The Non-Negotiables in 2026 These are the core capabilities that actually reduce risk and support business resilience. If you’re missing any of these — fix that first. 1. Identity-Led Security (MFA, SSO, Conditional Access) The perimeter is dead. Identity is the new firewall. Enforce MFA everywhere (not just “important” apps) Enable SSO to reduce credential reuse Use conditional access to stop session hijacks and geododging 🧠 If you don’t con...

Fortinet vs Cisco — Which One Should Aussie Businesses Choose?

Image
Two giants. Two different philosophies. One important decision. Whether you're refreshing a network, rolling out Zero Trust, or trying to simplify your security stack, chances are you've found yourself asking: “Do we go with Cisco — the enterprise veteran — or Fortinet — the integrated security upstart?” It’s not a casual question. The choice between these two vendors can define your architecture, operational model, and support experience for the next 3–5 years. And too often, it’s made for the wrong reasons — legacy bias, partner pressure, or sticker shock. This post unpacks how Fortinet and Cisco stack up for Australian businesses in 2025 , and how to decide what’s right for your org — not just the loudest vendor pitch. 🧭 Why This Comparison Matters in 2025 A few years ago, Cisco was the default. If you were a government agency, big bank, or national retailer, you bought Cisco. Fortinet? Often seen as “good enough” for smaller businesses. But that script has...

Why SMBs Should Care About SD-WAN (Even If They Don’t Know What It Is)

Image
Let’s be honest. If you're an Aussie SMB with under 200 staff, the term “SD-WAN” probably doesn’t mean much to you. It sounds technical, complex, and like something only big enterprises should care about. But here’s the thing — SD-WAN isn’t just for the big end of town anymore. If you’re still relying on aging MPLS links, clunky VPNs, or the “it’s always been this way” approach to networking, you’re already behind — and you’re probably paying too much for less performance. This post breaks down what SD-WAN is, why it matters for small and mid-sized businesses, and how it can save you money, boost performance, and get you ready for the cloud-first, security-conscious world we now live in. 🔍 What Is SD-WAN? (In Plain English) Let’s skip the jargon. SD-WAN stands for Software-Defined Wide Area Network . Think of it as the modern way to connect your offices, cloud apps, and remote workers — using cheaper internet links instead of expensive, rigid private circuits. Ol...

The Rise of Secure Cloud Connectivity: The New Australian IT Backbone (2025 Edition)

Image
1. Why Cloud Networking Has Overtaken the Data Centre It’s official: traditional on-prem data centres are no longer the heart of Australian enterprise networks. CIOs are shifting to cloud-native connectivity because: Cloud apps power 80–90% of daily work SaaS, IaaS, and PaaS dominate modern business Remote/hybrid teams need fast, secure, anywhere access Backhauling traffic through legacy hubs adds latency, cost, and risk. Today’s networks require direct-to-cloud, edge-aware, Zero Trust-aligned 2. AWS VPC Networking (Simplified) VPC = Your private AWS cloud environment Subnets = Organised traffic zones Security Groups = Firewalls that control access Connections = VPN, Direct Connect, or SD-WAN overlays To build a secure cloud-native network, visibility and segmentation are non-negotiable. 3. Cloudflare’s Role in Security & Performance Cloudflare is evolving beyond CDN: SASE platform for secure access Magic WAN ...

How to Future-Proof Your Network Refresh in Australia

Image
Stop Buying Hardware Start Buying Lifecycle Outcomes The days of big upfront hardware purchases are fading. Today’s successful IT teams don’t “buy boxes” they invest in business outcomes , performance SLAs , and scalable security . Leading Australian organisations are pivoting toward as-a-service offerings and smart lifecycle planning . This ensures fewer surprises, better forecasting, and faster adaptation to risks or new business needs. Key Tech to Consider in 2025 Wi-Fi 6E: Expanded spectrum (6GHz) enables faster speeds, lower latency, and better performance in dense environments. SD-WAN: Replace ageing MPLS. Enable traffic prioritisation, cloud offloading, and failover across hybrid links. Segmentation: Logical segmentation is key to Zero Trust. Eliminate flat, vulnerable networks. Network observability: End-to-end visibility is now essential across users, branches, and clouds. Vendor Strategy: Cisco vs Meraki vs Fortinet Feature Ci...

Why Networking, Security and Cloud Have Fully Converged in 2025

Image
Why Networking, Security and Cloud Have Fully Converged in 2025 Published: October 2025 Estimated Read Time: 6–8 minutes Author: Ateeq Sheikh | TheCyberGuyAU The Death of the Siloed IT Buying Model In 2025, traditional, siloed IT procurement is no longer viable. Security, networking, and cloud infrastructure are now so interconnected that treating them separately introduces friction, complexity, and risk. Businesses that haven’t integrated these functions are falling behind. Why Networking Is Now a Security Architecture Every network decision now has direct cybersecurity implications. From firewall placements to DNS routing, your network is the first line of defence. Network architecture must now be designed with threat modelling, segmentation, and identity-first access in mind. SD-WAN Replacing Legacy WAN Legacy WAN architecture often based on MPLS and hub-and-spoke models can’t keep up with cloud-era demands. SD-WAN offers agile, policy-driven routing, applicatio...

Why Penetration Testing Is Just the Beginning of Your Cybersecurity Journey

Image
  By Ateeq Sheikh, CyberGuyAu Published:  November 2025 Estimated Read Time: 8–10 minutes Tags: #CyberSecurity #PenetrationTesting #RiskManagement #ZeroTrust #SMB #AustraliaCyberSecurity #EssentialEight Introduction: The Myth of the "One-and-Done" Pen Test Too many Australian organisations especially in the SMB and education sectors view penetration testing as the end goal of cybersecurity. You tick the compliance box. You fix a few things. You move on. But here’s the hard truth: a pen test is a snapshot in time, not a strategy . It’s the beginning not the end of building real, sustained cyber resilience. In today’s threat landscape, where ransomware syndicates and nation-state actors are targeting Australian businesses more aggressively than ever, relying solely on annual pen testing is not just risky it’s negligent. What Is Penetration Testing, Really? Penetration testing (or "pen testing") simulates real-world cyberattacks to uncover vulnerabilitie...

Nation-State Breach at F5: What It Means for Enterprise Security in 2025

Image
Published: October 2025 Estimated Read Time: 6–8 minutes Author: Ateeq Sheikh | TheCyberGuyAU Focus Tags: #Cybersecurity #SupplyChain #NationState #F5Breach #ZeroTrust #EnterpriseSecurity Executive Summary: F5, a Fortune 500 cybersecurity firm trusted by 48 of the Fortune 50 companies, has disclosed a nation-state cyberattack that penetrated its internal systems — including development environments for its flagship BIG-IP platform. The breach exposed source code, undisclosed vulnerabilities, and select customer configurations. While F5 claims no active exploitation or supply chain compromise has occurred, the breach underscores an urgent reality: critical infrastructure is now a priority target for nation-state threat actors. What Happened? Date Discovered: August 9, 2025 Impact Scope: BIG-IP product development environment Internal knowledge management systems Source code and vulnerability data exfiltrated Configuration details for a li...

Australia’s Cyber Threat Landscape 2024–2025: What Every Business Needs to Know

Image
Updated: October 2025 | Author: Ateeq Sheikh – TheCyberGuyAU Australia is facing a cyber reckoning. The 2024–2025 Annual Cyber Threat Report from the Australian Cyber Security Centre (ACSC) reveals a fast-evolving threat landscape that’s not just technical—it’s personal, economic, and national. From ransomware gangs to state-sponsored espionage, the threats are growing smarter, faster, and more targeted. If your business still views cybersecurity as an IT task instead of a core business risk, this report should be your wake-up call. Why Australia Remains a Prime Target Australia’s increasing global significance, tech innovation, and economic prosperity make it a high-value cyber target. The Indo-Pacific's geopolitical instability—combined with growing digital adoption—has drawn the attention of state actors and cybercriminal networks alike. The ACSC’s findings underscore how deeply embedded these threats now are across our digital landscape. By the Numbers: A Year of Rele...